Spring AMQP CVE-2017-8045 Remote Code Execution Vulnerability
BID:100936
CVE-2017-8045 |Info
Spring AMQP CVE-2017-8045 Remote Code Execution Vulnerability
| Bugtraq ID: | 100936 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-8045 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2017 12:00AM |
| Updated: | Sep 19 2017 12:00AM |
| Credit: | Man Yue Mo from Semmle and lgtm.com. |
| Vulnerable: |
Pivotal Spring AMQP 1.5.5 Pivotal Spring AMQP 1.5.4 Pivotal Spring AMQP 1.0 Pivotal Spring AMQP 1.6 M2 |
| Not Vulnerable: |
Pivotal Spring AMQP 2.0 Pivotal Spring AMQP 1.7.4 Pivotal Spring AMQP 1.6.11 Pivotal Spring AMQP 1.5.7 |
Discussion
Spring AMQP CVE-2017-8045 Remote Code Execution Vulnerability
Spring AMQP is prone to remote code execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7 are vulnerable.
Spring AMQP is prone to remote code execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7 are vulnerable.
Exploit / POC
Spring AMQP CVE-2017-8045 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Spring AMQP CVE-2017-8045 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Spring AMQP CVE-2017-8045 Remote Code Execution Vulnerability
References:
References:
- Spring Framework Homepage (GoPivotal)
- CVE-2017-8045: Remote code execution in spring-amqp (Pivotal)